Summary
The remote host is missing an update to gallery
announced via advisory DSA 512-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20512-1
Insight
A vulnerability was discovered in gallery, a web-based photo album written in php, whereby a remote attacker could gain access to the gallery admin user without proper authentication. No CVE candidate was available for this vulnerability at the time of release.
For the current stable distribution (woody), these problems have been fixed in version 1.2.5-8woody2.
For the unstable distribution (sid), these problems have been fixed in version 1.4.3-pl2-1.
We recommend that you update your gallery package.
Severity
Classification
-
CVE CVE-2004-0522 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities